Ok, so if I understand correctly the version that comes out from the installation DVD (RELEASE) receives security fixes. To have BINARY upgrades also for "generic" fixes, like the ZFS ones, I should switch to STABLE.
The second question now is, since I cannot use freebsd-update to "upgrade" to...